Sceawere
Vulnerability Detail
CVE-2026-105113UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Nezha Dashboard Mutex Deadlock Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- nezhahq
- Product
- nezha
- Attack Type
- Improper Locking
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-03T14:16:37.823Z",
"pubdate": "2026-10-03T14:16:37.823Z",
"executiveSummary": "Nezha Dashboard versions 1.8.0 through 2.3.12 are susceptible to an improper locking vulnerability within the alerting subsystem.\nThe flaw stems from a non-deferred mutex unlock occurring on a nil-map panic path, which leads to a permanent deadlock of the notification engine.\nAn authenticated non-admin attacker can exploit this condition by issuing a sequence of four specific notification API calls, effectively disabling alerting functionality for the entire system.\nFollowing the initial deadlock, the application becomes vulnerable to memory exhaustion as blocking requests accumulate in the service queue.\nThis vulnerability poses a significant denial-of-service (DoS) risk, as it permits low-privileged users to disrupt critical monitoring and alerting workflows while potentially compromising system stability through heap memory pressure.\nSuccessful exploitation requires valid authentication to the dashboard, but does not necessitate administrative privileges, broadening the threat landscape to include any registered user.",
"technicalDetails": "The vulnerability resides in the concurrency management logic of the Nezha Dashboard alerting subsystem. The root cause is a race condition and error-handling deficiency where a sync.Mutex is released without the use of a defer statement during a panic sequence triggered by a nil-map access.\nUnder normal operations, the alerting service utilizes a mutex to synchronize access to notification state objects. When an unexpected condition triggers a nil-map dereference, the runtime panics. Because the mutex unlock operation is not wrapped in a defer block, the unlocking call is bypassed when the execution flow is interrupted by the panic. This results in the mutex remaining in a permanently locked state.\nAn attacker can exploit this by triggering the specific code path associated with the notification API. By sending four carefully crafted notification API requests, the attacker induces the panic condition, causing the alerting subsystem to halt. Once the mutex is leaked in an locked state, all subsequent attempts by the application to access the alerting subsystem result in threads blocking indefinitely as they wait to acquire the held lock.\nThe attack flow follows these steps: 1. The attacker authenticates to the Nezha Dashboard. 2. The attacker submits a series of four malicious or malformed notification-related API requests. 3. The server-side logic triggers a nil-map dereference, which initiates a panic. 4. Due to the lack of a deferred mutex unlock, the synchronization primitive is left in a locked state during the panic recovery or process crash handling. 5. The alerting subsystem becomes unresponsive, and subsequent incoming requests to the alerting module are queued and blocked.\nThe post-exploitation impact extends beyond the loss of alerting functionality. Because the incoming requests to the alerting service are blocked and held in memory, the application experiences a rapid increase in memory consumption. If sustained, this leads to heap exhaustion, potentially causing the entire Nezha Dashboard process to crash, resulting in a full denial-of-service condition.\nThis vulnerability affects Nezha Dashboard versions from 1.8.0 up to 2.3.12. It is highly exploitable by any authenticated user who has access to the notification API endpoints, as no further administrative privileges are required to reach the vulnerable code path."
}